Stolen, not given: accounts broken into for explicit content
In August 2026 the FBI warned that sexual exploitation actors are illegally accessing victims' social media and personal accounts to steal explicit content and sell it on criminal marketplaces — often without the victim ever knowing. The intrusion methods are ordinary account-takeover techniques, including one that turns on persuading the victim to hand over a verification code.
- Year
- 2026
- Where
- United States
- Outcome
- Ongoing
- Victims
- Not stated in the sources
- Schemes
- Sextortion, Phishing and smishing, SIM swap
- Last reviewed
- 2026-09-06
The facts, as recorded
- IC3 advisory issued 10 August 2026, covering both adult and underage victims.
- Content is stolen from accounts, typically without the victim's knowledge, then posted in forums or sold on illicit marketplaces.
- Personally identifiable information — name, date of birth, email, phone number, social media username — is often posted alongside the content.
- Method one: high-volume password and PIN attempts using curated lists from data leak sites, social media and open sources.
- Method two: a text claiming the victim's social media account will be disabled unless they reply with a verification code — the actor then triggers a password reset and uses the code the victim sends.
- Method three: look-alike domains and emails imitating social media customer support, notifying the victim of a 'new login' with a malicious password-change link.
- The FBI notes victims often face re-victimisation through harassment, sextortion and stalking.
Why this case matters
This advisory describes a version of the crime in which the victim participates in nothing at all.
The familiar sextortion story involves an exchange — images shared with someone the victim believed they were in a relationship with. This is different: accounts are broken into, private content is taken, and it is posted or sold, frequently before the victim knows anything has happened.
That removes the last thread of victim-blaming that clings to this offence. There is no decision to regret and no message to wish unsent.
The technique that matters most
Of the three methods the FBI lists, one deserves particular attention because it defeats two-factor authentication without breaking it.
The actor sends a text claiming the victim’s social media account is being disabled or locked unless they reply with a verification code. Then the actor requests a password reset, which sends a genuine code to the victim’s phone. The victim, expecting a code, forwards it — and the account is gone.
The code was real. The system worked. The only thing that failed was the assumption that a code arriving means the person asking for it is legitimate.
The rule this produces
It is the same rule that appears on the safe account and phishing pages, and it is absolute:
A verification code is never to be shared with anyone, for any reason. Not with support, not to prove your identity, not to stop an account being disabled, not to cancel something. The code exists to stop whoever is asking for it. A password reset you did not start is a break-in attempt in progress, and the correct response is to change your password directly rather than to reply to anything.
What it tells you about the scheme
The advisory also notes that stolen content is published alongside the victim’s name, date of birth, phone number and username — which converts one intrusion into an open invitation for harassment, stalking and further sextortion by unrelated people.
That is why the reporting advice on this site treats account compromise as urgent even where nothing has obviously been taken. The window between an account being accessed and the content being distributed is the only point at which any of this can be limited.
Sources
- Sexual Exploitation Actors Stealing and Leaking Explicit Content. FBI Internet Crime Complaint Center. Accessed 2026-09-06. Supports: Every detail above: the theft-and-resale model, the three intrusion methods, the PII exposure and the re-victimisation warning.